URLhaus Database

You are currently viewing the URLhaus database entry for http://vics.com.sg/aspnet_client/protected-module/open-l1w8jvc2-v6589vnm/OQlIe0H8-jhk6jlqq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288814
URL: http://vics.com.sg/aspnet_client/protected-module/open-l1w8jvc2-v6589vnm/OQlIe0H8-jhk6jlqq/
URL Status:Offline
Host: vics.com.sg
Date added:2020-01-15 06:25:05 UTC
Last online:2020-01-20 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-15 06:26:02 UTC to abuse{at}netdeploy[dot]com)
Takedown time:5 days, 9 hours, 3 minutes Bad (down since 2020-01-20 15:29:55 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-15Untitled_17057 786875211.docdoc e4a2fb5287ef2620ece2c90499b31d9b32d278abb562a7510cda42a965c2101eVirustotal results 25.81% Heodo
2020-01-15FILE 673198260-921.docdoc 09aaf59e8836f2b712c0394624b450ec5c3034c050c3c1aede62c93d43d4839en/a 
2020-01-15Untitled_001088 236187.docdoc 789f9210cab6cd5d82f2eb8839d8f8681a18cd0e7cc05d4871ee30adf22833eaVirustotal results 22.95% Heodo
2020-01-15Untitled-138 023361749.docdoc 20f965f623b909bbd5f8901446460bb49fe57d4bd89c0949d80f94a701aef92fVirustotal results 22.58% Heodo
2020-01-15Untitled 361251 292.docdoc 2643b7c39e5ee1c738ff00da841b165c9db63557280f78bdcec21ae5443ca352Virustotal results 18.33% Heodo
2020-01-15UNTITLED_401505.docdoc de169ea387921f8260881d702a6ec1c957e9f2ae3ce0916c2c5f2e299489cbd4n/a Heodo
2020-01-15FILE.docdoc 4568f0c98f66cd4bb25f795a700ff723b776f24f6ee3840743f2275ce9d5a7e3Virustotal results 38.33% Heodo